logo

Zloader With a New Infection Technique

ID: 34509347-4d29-5a75-a4b1-2a927dde530d

STIX ID: report--34509347-4d29-5a75-a4b1-2a927dde530d

Feed Name: McAfee Labs Blog

Threat Score
70/100

Date Published: 2021-07-08

Date Updated: 2026-04-28

Author: McAfee Labs

...
...

This McAfee Labs analysis details a Zloader infection chain: phishing emails deliver a malicious Word document which downloads a password-protected Excel file; the Word VBA reads cell contents and writes macros into the Excel file, modifies registry settings to disable Excel macro warnings, and triggers an Auto_Open macro that downloads a Zloader DLL (.cpl) and executes it via rundll32. The report includes IOCs (SHA-256 hashes and download URLs), detection signatures, mitigation advice, and mappings to relevant MITRE ATT&CK techniques.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.